AWS re:Invent 2025 - AWS Security Hub: Unifying & simplifying security operations at scale (SEC228)
AWS Events
6 views • Save 40 min (10 min read) • 7 months ago
Video Summary
AWS Security Hub has undergone a significant evolution, transitioning from a cloud security posture management (CSPM) tool to a comprehensive security operations platform. This enhancement integrates signals from various AWS native security services like GuardDuty, Inspector, and Macie, as well as partner tools, to provide unified visibility, context, and automated response capabilities. A key innovation is the introduction of "exposure findings," which correlate multiple security signals to identify high-risk scenarios, offering prioritized insights and attack paths. The service also now features simplified, resource-based pricing and standardization of findings using the Open Cyber Security Schema Framework (OCSF), aiming to reduce complexity and cost for customers.
The updated Security Hub aims to address customer pain points by unifying disparate security signals, providing richer context for detections, and enabling automated remediation. Innovations include near real-time correlation of traits to generate exposure findings, detailed attack path visualizations, and simplified enablement across multiple accounts and regions. This evolution allows security teams to move from a fragmented approach to an integrated and unified security strategy, empowering them to prioritize and act on critical threats more effectively, as demonstrated by customer use cases that highlight improved workflow integration and reduced operational overhead.
Short Highlights
- AWS Security Hub has evolved into a unified security operations platform, integrating signals from native services and partners.
- New "exposure findings" correlate multiple security signals to identify and prioritize high-risk scenarios with detailed attack paths.
- The service now offers simplified, resource-based pricing for better predictability and cost management.
- Findings are standardized using the Open Cyber Security Schema Framework (OCSF) to ease downstream integrations.
- Simplified enablement allows for the configuration of multiple security services across accounts and regions from a central console.
Related Video Summary
Key Details
Evolution of AWS Security Hub [00:04]
- Key improvements and innovations in AWS Security Hub are highlighted, focusing on unification, simplification, automated response, and remediation.
- Security remains a top priority, especially in the context of AI and GenAI advancements, with customers seeking unified visibility into their resources and configurations.
- The evolution addresses customer needs for context in security detections, enabling faster and more meaningful response actions.
- Disconnected security signals from various tools can hinder rapid response, necessitating normalization and automation.
- The core theme is transforming a fragmented security approach into an integrated and unified one.
"The theme for Security Hub from the very beginning of the evolution is to how to change that fragmented security approach into an integrated and unified security approach."
Unified Signal Correlation and Context [04:22]
- Security Hub now brings together signals from AWS native security services (GuardDuty, Macie, Inspector) and partner tools.
- These signals are enriched and correlated to provide a unified view of emerging threats and their impact on resources.
- Correlation with context allows security teams to see the full picture of a threat's emergence, path, and impacted resources.
- This leads to streamlined response and reduced mean time to respond.
- The service is now generally available with these key features, unifying security signals and improving user experience.
Native Services Integration and Enriched Attack Paths [06:20]
- Example scenarios demonstrate how native services contribute to Security Hub's enriched view.
- GuardDuty identifies brute-force attacks, Inspector detects vulnerabilities, and CSPM (Security Hub) flags misconfigurations on an EC2 instance.
- Previously, these findings were separate; now, Security Hub correlates them to provide a unified, enriched attack path.
- This allows for a clear view of one risk resource and the severity of its associated threats.
- The concept extends to network exposures, resource control policies, and sensitive data exfiltration, providing context compared to simpler risks.
"These three findings earlier resided in security hub but there was no correlation and there was no context so what we've done now is unified that and provided customers with one enriched attack path that you can look at."
Real-time Analysis and Partner Integrations [09:51]
- Since its preview, Security Hub has enhanced correlation and analysis using AI and machine learning for real-time trend and risk analysis.
- The service integrates with security partners downstream for automation and remediation workflows, feeding events into SIEM or orchestration tools.
- These improvements, developed during the preview period, are now generally available.
- Key benefits include a unified operations view, enriched user experience, context-driven prioritization, and faster response and remediation.
Simplified Enablement and Asset Inventory [10:54]
- Security Hub remains under the same name to reduce customer confusion, now truly acting as a central hub for security operations.
- It aggregates findings from control evaluations, native AWS security services, and partner tools, building on CSPM capabilities.
- Existing users can continue using the standalone CSPM service, with an option to opt into the new features via a 30-day free trial.
- Centralized management across multiple AWS accounts and regions is a key feature, allowing unified configuration.
- The asset inventory provides a view of which accounts and resources are protected for threats, vulnerabilities, and misconfigurations.
"Security Hub now truly becomes a security hub where we're not only bringing in the previously known findings of control evaluations where it was a centralized monitoring tool that evaluated misconfigurations across your resources and also aggregated all the findings from our native AWS security services as well as from our partner tools."
Exposure Findings and OCSF Standardization [15:13]
- Security Hub uses AI/ML to correlate findings and generate "exposure findings," an elevated combination of multiple signals.
- These findings are built on traits like misconfiguration, sensitive data detection, network reachability, or data exposure.
- Exposure findings offer a faster way to act on risks with prioritization.
- Security Hub normalizes all findings into an open standard format, the Open Cyber Security Schema Framework (OCSF).
- OCSF simplifies integration with downstream products and aids in alert triage, benefiting both internal findings and partner inputs.
Unified and Simplified Pricing [17:04]
- Customer feedback highlighted the need for simplified and predictable pricing, moving away from variable components.
- Security Hub now offers unified pricing, consolidating threat detection, vulnerability management, sensitive data detection, and CSPM into a single invoice.
- Pricing is now deterministic and resource-based, making it easier to forecast costs.
- The pricing model is pay-as-you-go monthly, offering flexibility without long-term contracts.
- This simplification extends to the overall ease of use and cost management of the service.
"So one of the key elements that we launched yesterday since the preview that you can now experience is the unified pricing and simplified pricing within security hub as well."
Partner Integrations and Automated Response [20:21]
- Integration with partner tools for downstream response and orchestration is crucial.
- Security Hub facilitates easier integration with tools like Jira, ServiceNow, Tines, Securonix, and Splunk.
- This is enabled by the OCSF standardization, allowing partners to automate workflow events and investigations.
- The integration with CloudWatch Unified Data Store further simplifies investigation processes.
- All findings in Security Hub are standardized in OCSF format, simplifying downstream integrations and investigations.
Key Features of the New Security Hub Experience [23:50]
- Scott Ward discusses key features like "exposures" which help prioritize findings by identifying weaknesses in software packages, configurations, or best practices.
- Exposures are generated by correlating traits from various security services (Inspector, GuardDuty, CSPM, Macie) and resource inventory data.
- These traits are categorized into assumability, misconfigurations, reachability, sensitive data, and vulnerabilities.
- Severity is determined by ease of discovery, ease of exploit, likelihood of exploit, awareness, and impact.
- The correlation for exposures now happens in near real-time, providing quicker insights.
"So with exposures, what we're working on is the exposures are meant to be that prioritization that helps you figure out where should I be spending my time and who should I be giving these things to to to my team to to work on."
Exposure Examples and New Signals [30:11]
- An example illustrates how a combination of traits (vulnerability, internet reachability, sensitive data access, misconfiguration) results in a single exposure finding.
- New signals being incorporated into exposure correlation include end-of-life operating systems, malicious software packages identified by Inspector, and malicious files detected by GuardDuty.
- These new signals, combined with existing ones like brute-force attempts, provide a more comprehensive view for prioritization.
Simplified Enablement and Configuration Catalog [34:51]
- Security Hub simplifies the enablement of various AWS security services across multiple accounts and regions.
- Customers can configure policies from their AWS Organizations management account, delegating administration to manage configurations centrally.
- This process enables services like GuardDuty, Security Hub CSPM, and Inspector across chosen accounts and regions.
- Region aggregation can centralize all security findings in one region for easier viewing.
- A configuration catalog allows users to select predefined security essential bundles or customize capabilities based on their needs.
"And so what we've done with the simplified enablement here is that we've actually set it up so across those different security services, security hub, guard duty, security hub, CSPM, and inspector. The steps you would take, you would go into your organization management account."
Account Coverage Dashboard and Trends Feature [39:40]
- Visibility is provided through an account coverage dashboard, showing where Security Hub is enabled and the coverage across security services.
- The trends feature offers insights into security posture over time, showing period-over-period changes in threat findings, exposure findings, and active resources.
- This feature helps management understand trends, identify improvements, and assess progress towards security goals.
Customer Journey with Security Hub at Awesome [41:34]
- Lee Lison from SmugMug and Flickr (Awesome) shares their experience with Security Hub, highlighting the need for risk identification and prioritization over 19 years of AWS usage.
- They previously had findings from multiple sources but lacked correlation and context, making prioritization and routing difficult.
- Security Hub's integration with existing tools, ability to send notifications to Jira/Slack, and unified enablement (though not fully utilized in preview) are key benefits.
- Features like resource inventory and near real-time risk analytics are crucial for timely and impactful findings.
"But we didn't have any correlation between these findings. There was no context. Without that, it was hard to prioritize and route findings."
Workflow Automation and Team Integration [45:35]
- Awesome's workflow ingests findings from GuardDuty, Security Hub, CSPM, and Inspector into Security Hub as a single pane of glass.
- Automations filter noise, identify critical signals, and route tickets directly to the teams responsible for the infrastructure, rather than a generic security bucket.
- This empowers builders with context in their daily tools like Jira, turning security from a gatekeeper into a partner.
Continued Evolution and Wishlist [48:22]
- Awesome sees Security Hub as a single pane of glass for deeper insight into findings from any source, beneficial for both technical and non-technical teams.
- The trends feature provides a view of their security posture, and easier research for findings saves engineer time.
- Their wishlist includes bundled configuration and pricing for AWS security tools, tighter Slack integrations, better Jira grouping, and future integrations with AWS security agents and incident response teams.
- The new features build a foundation to keep their promise of keeping customer photos and businesses safe and secure.
Key Takeaways and Getting Started [49:08]
- Security Hub unifies security services for centralized visibility and maintenance, aiding prioritization of critical environmental items.
- It helps teams focus efforts and wake up to critical issues with the right prioritization.
- The service enables teams to do more with less by bringing services together and assisting with prioritization.
- A 30-day free trial is available, and feedback is encouraged for continuous improvement.